Restricting network access using Linux Network Namespaces
blog.sigma-star.at
blog.sigma-star.at
>Please note that network namespaces, actually Linux namespaces in general, have no influence on existing file handles. Therefore, if your application possesses a file handle to a socket from another network namespace, it can use it in the new network namespace smoothly.
>This is a useful feature as it allows creating network servers that can serve a listening socket but are disconnected from the outside world. If an attacker manages to overtake the application, they are unable to create a new socket. Here you can find a sample application that outlines the idea.
[0]: https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/
What I really would like more discussed is _network_ isolation. You don't need root to exfiltrate tons of data.
If you implement socket activation and use an empty network namespace your service can be totally disconnected from any network and still handle requests (because the socket FD it listens on was inherited from systemd). This makes exfiltration much more difficult.
https://skarnet.org/software/s6/s6-fdholderd.html
Sounds like you could benefit from Qubes OS.
I've done similar things (and sometimes with a wireguard tunnel out to internet) for privacy reasons.
- https://adil.medium.com/container-networking-under-the-hood-...